Updated 16 November 2022
This policy covers the following topics:
- Information we collect
- How we use and share your personal information
- Bank Connect
- Protection of your information
- Access to and correction of your personal information
- How long we hold your information for
- Changes to this policy
- How to get in touch with us
Information we collect
When using or seeking to use our services we collect the information you provide to us including:
- Personal information such as your name, address, gender, date of birth, drivers licence number, passport, 18+ card, Kiwi Access card, New Zealand Visa issued by New Zealand Department of Immigration, or other identification data;
- Contact information such as your phone number, address and email address;
- Financial information such as credit score, bank statements, utility bills, partial card numbers and card expiry dates (we do not collect or hold full card numbers, which are held by the payment gateway), and your repayment and default (if any) history; and
- Information about your digital footprint, including your IP address, device type, web browser, and operating system.
In addition we may collect information from you when you communicate with us or our service providers (in writing or verbally) such as communicating with our customer support or when you participate in any survey, promotion or competition we may run.
As part of our assessment of fraud and credit suitability, we also utilise third parties and may collect personal information from third parties such as credit agencies and identity verification providers and other commercial information service providers. We may also access personal information about you that is available publicly, such as on public and subscribed registers, and details you have shared publicly on social media platforms, which may be used to supplement our customer database.
We may also collect certain digital information from any retailer where you are seeking to use our Services including personal information such as your full name, mobile phone number, email address, what you are purchasing, cost of purchase and shipping details.
We may also collect information from your computer or device in relation to your use of our website or Zip Co NZ Platform such as IP address, activity logs, cookie and browser identifiers, operating system identifiers and location identifiers.
Using and sharing your personal information
We will primarily use your personal information in order for us to provide our Services to you or assess your suitability for us to provide such Services.
This includes, but is not limited to using your personal information to:
- Make decisions to provide you with our Services, including evaluating your creditworthiness or verifying your identity;
- Provide to our third party service providers to assist us in determining your identity or suitability for our Services;
- Provide you with our Services, including the arrangement of the instalment plan and responding to any queries and providing any information about us;
- Improve, customise and enhance our Services, Platform and Website;
- Manage your scheduled instalment payments and default fees (if any) and manage the Services we provide;
- Communicate with you via phone, text message, notifications, email or post and otherwise to manage our relationship with you;
- Manage and prevent fraud and other risks to our business;
- Provide you with marketing materials and other news updates and promotions with respect to our products and services. You may elect to opt out of any marketing information we send to you by following the link in any relevant information;
- Where you have accessed our Service from any Warehouse retailer, where Warehouse is the credit provider and Zip Co NZ is processing agent, we may use your personal information to consider your suitability for using our Service if you subsequently access our service via any merchant or retailer not part of the Warehouse group;
- Comply with any relevant law or legal obligations;
- Contribute to statistical and analytical data relating to your buying habits.
We do not sell or provide access to your personal information to third parties for them to market direct to you without your consent. However, we may share your personal information with third parties for the following purposes:
- To our payment system providers or retailers in order to manage a transaction or respond to a query or complaint or improve their service offering;
- To enforce our rights including debt collection and assigning debts to third party debt collection agencies;
- To our investors, potential acquirers and/or financiers;
- To our commercial partners and credit agencies to enable them to improve their services to us and to you;
- To our third party service providers, engaged to perform services on our behalf such as text messaging and email services;
- We may share information relating to your instalment arrangements with us including your repayment history and any non- compliance or default history. A credit reporter may hold such information on their database and use it for providing credit reporting services to other users of the credit bureau; and
- We may share information relating to your personal creditworthiness, including your credit score, age, where you have shopped and geographical location to persons involved in providing funds by way of securitisation.
Where your personal information has been utilised in the development of any statistical or analytical data and has been aggregated and anonymised, we may sell, distribute and disclose such data to retailers and other third parties.
With your consent, we may ask you to share your personal and financial information (including
your personal online banking details and online account and card statements) with our third
party service providers, to enable them to perform digital data capture (the collection and/or
copying of your screen display data, including financial information, from the Platform) on our behalf for the purposes of assessing your affordability.
Protection and storage of your personal information
Your personal information will predominantly be stored in electronic form in secure cloud based data centres located in New Zealand or overseas that may be owned by third party service providers. Your personal information may also be stored in paper form. All such information whether electronically or physically stored is kept secure using generally accepted standards of security.
When we store your personal information, we will take reasonable steps to keep your information secure and to prevent unauthorised disclosure.
Access and correction of your personal information
Subject to any applicable exceptions set out in the Privacy Act, you have the right to request access to or correction of personal information we hold about you by contacting us using the details below.
1. Clicking “Unsubscribe” or replying “STOP” to any electronic marketing or SMS messages
or offers you receive;
2. Updating your Notification preferences on your mobile device;
3. Submitting a request via the Help Centre; or
4. Contacting us via phone at 09 4898144.
After you’ve opted-out of receiving marketing communications, we may still contact you for
transactional or informational purposes.
We use technology known as “cookies” to collect certain information about you when internet browsing or device applications. Cookies can record information about your visit to our website. This enables us to provide a more customised experience next time you visit. You can switch off cookies by adjusting your web browser settings.
How long we hold your information
We will hold your personal information only for as long as necessary to achieve the purpose for which we collected it for and in order to comply with any relevant law or legal obligation.
PCI DSS Policy
For security purposes, Zip Co NZ does not keep or hold your full debit or credit card data. We use Payment Express, New Zealand’s largest payment gateway. Payment Express adhere to a comprehensive set of requirements created by the Payment Card Industry Security Standards Council for ensuring the safe handling of sensitive customer debit and credit card data. Payment Express is a Level 1 Service Provider and is compliant to PCI DSS Version 3.2 standard. More information can be found here.
Changes to this policy
How to get in touch with us
If you have any questions regarding this policy or should you wish to lodge a complaint in relation to our use or disclosure of personal information, you can contact us here or email the Privacy Officer at [email protected]
If you are unsatisfied with our response or privacy practices, you have the right to make a complaint to the Office of the Privacy Commissioner at:
PO Box 10094
Phone: 0800 803 909